๐ ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ถ๐ฒ๐น๐ฑ โ Real-World Findings from Security Assessments
๐ฅ ๐ฑ๐ณ.๐ญ%ย of infrastructures Iโve assessed ๐ฎ๐น๐น๐ผ๐ ๐ฎ๐น๐น ๐๐ฒ๐ฟ๐๐ฒ๐ฟ๐ ๐๐ผ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐๐ต๐ฒ ๐ถ๐ป๐๐ฒ๐ฟ๐ป๐ฒ๐ย โ without restrictions.
This is surprisingly common โ and honestly, hard to understand.
๐ฌ๐ฒ๐, ๐๐ผ๐บ๐ฒ ๐๐ฒ๐ฟ๐๐ฒ๐ฟ๐ ๐ป๐ฒ๐ฒ๐ฑ ๐ผ๐๐๐ฏ๐ผ๐๐ป๐ฑ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ (DNS, Entra ID Connect, WSUS…), but that doesnโt mean all of them should have it โ especially not without any filtering.
๐ฃย ๐๐๐น๐น ๐ผ๐๐๐ฏ๐ผ๐๐ป๐ฑ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐บ๐ฎ๐ธ๐ฒ๐ ๐ถ๐ ๐๐ฟ๐ถ๐๐ถ๐ฎ๐น ๐ณ๐ผ๐ฟ ๐ฎ๐๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ ๐๐ผ:
๐บ Exfiltrate data
๐บ Connect to C2 infrastructure
๐บ Establish persistent tunnels
On top of that, once admins get used to this level of access, ๐๐ต๐ฒ๐ ๐ผ๐ณ๐๐ฒ๐ป ๐ฎ๐ฏ๐๐๐ฒ ๐ถ๐ ๐๐ผ ๐ฑ๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ ๐๐ผ๐ผ๐น๐ ๐ฎ๐ป๐ฑ ๐๐ฐ๐ฟ๐ถ๐ฝ๐๐ directly to critical servers โ including domain controllers. Thatโs how mistakes happen (or worse: malware lands).
๐ซ ๐๐น๐ผ๐ฐ๐ธ ๐ฎ๐น๐น ๐ผ๐๐๐ฏ๐ผ๐๐ป๐ฑ ๐ฐ๐ผ๐บ๐บ๐๐ป๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฏ๐ ๐ฑ๐ฒ๐ณ๐ฎ๐๐น๐. Allow only whatโs truly needed.
๐๏ธ ๐จ๐๐ฒ ๐ฉ๐๐๐ก ๐๐ฒ๐ด๐บ๐ฒ๐ป๐๐ฎ๐๐ถ๐ผ๐ป to slow malware spread and improve infrastructure manageability.
๐๐ณ ๐๐ผ๐’๐ฟ๐ฒ ๐๐ป๐๐๐ฟ๐ฒ ๐๐ต๐ถ๐ฐ๐ต ๐ฝ๐ผ๐ฟ๐๐ ๐ฎ๐ฟ๐ฒ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐ป๐ฒ๐ฒ๐ฑ๐ฒ๐ฑ in a secure Windows environment, I created a reference guide to help you:
https://academy.horizon-secured.com/p/ad-network-ports
